Behind the scenes in the Expel SOC: Alert-to-fix in AWS
ID: 4289a190-2717-543d-8c64-37fbced05356
STIX ID: report--4289a190-2717-543d-8c64-37fbced05356
Feed Name: Expel Blog
Date Published: 2020-07-28
Date Updated: 2026-04-27
Author: Jon Hencinski; Anthony Randazzo; Sam Lipton; Lori Easterly
Over the July 4th weekend Expel’s SOC detected that a compromised AWS root access key was used to create SSH key pairs, spin up ten c5.4xlarge EC2 instances, and connect to a Monero mining pool; the team used CloudTrail and GuardDuty signals plus automated tooling to triage, escalate to the Global Response Team, and contain the incident within 37 minutes by removing the stolen key, terminating instances, and deleting malicious security groups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
